skills/b-open-io/1sat-sdk/sweep/Gen Agent Trust Hub

sweep

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill describes the use of private keys (in WIF format) to authorize the sweeping and migration of blockchain assets. While necessary for the stated functionality, this involves the handling of sensitive cryptographic material within the agent context.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to an external indexing API at api.1sat.app to retrieve unspent transaction output (UTXO) data for specific blockchain addresses.
  • [COMMAND_EXECUTION]: The installation instructions require the execution of package manager commands to install necessary Node.js dependencies, including @1sat/actions, @1sat/wallet, and @bsv/sdk.
  • [PROMPT_INJECTION]: The skill processes untrusted data fetched from the external api.1sat.app service. Because this data is used to construct blockchain transactions without explicit sanitization or boundary markers, it presents an indirect prompt injection surface. (Ingestion: api.1sat.app; Boundaries: Absent; Capability: sweepBsv.execute; Sanitization: Absent).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 03:12 PM